The $1.5B Bybit Hack
blog.trailofbits.com
The $1.5B Bybit Hack
1–10 of 140 posts
Re: The $1.5B Bybit Hack
#2If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that doesn't sound like cold storage to me.
Re: The $1.5B Bybit Hack
#3Re: The $1.5B Bybit Hack
#4My understanding is this multisig failed because, like most security, everyone just pressed yes and didn’t communicate, investigate, or ask questions, defeating the purpose of a multisig.
Re: The $1.5B Bybit Hack
#5- The multisig smart contract is owned
- The computer you're signing on is owned
- The hardware wallet (ledger, trezor) you're using is owned
The multisig contract in question here (Gnosis Safe) has shown to be incredibly robust, and hardware wallets are very difficult to attack, so the current weak point is the computer.
Cryptocurrency companies need to start solving this by moving to a more locked-down, dedicated machine for signing, as well as actually verifying what is shown on the tiny hardware wallet screen instead of blindly clicking "yes".
Re: The $1.5B Bybit Hack
#6My understanding is this multisig failed because, like most security, everyone just pressed yes and didn’t communicate, investigate, or ask questions, defeating the purpose of a multisig.
The concept of strong safeties was not in place. Safeties refer to layers that go beyond common trust mechanisms. In this case, signing a transaction of that magnitude solely based on multi-signature approval was completely insufficient. There should have been additional safeguards, such as special approvals and extra verification steps, specifically designed for transactions within that amount range.
Re: The $1.5B Bybit Hack
#7I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug.
I feel like securing something like this is practically impossible. There's always the risk of a bad actor who introduces malware for a small fee.
[1]: https://www.chainalysis.com/blog/2024-crypto-money-launderin...
Re: The $1.5B Bybit Hack
#8While it is nearly impossible to steal $100mn from one of the mega-banks, those crypto bros, a bunch of failed morons (self-proven by all these hacks), manage to lose people's money. Now.. I am not defending the banking system (and its ethics/morals), but damn-it they do a f-a-r better job at IT Audit/IT Compliance/IT Sec (my bread and b utter for decades).
Re: The $1.5B Bybit Hack
#9Re: The $1.5B Bybit Hack
#10In a multisig interaction there are 3 ways to get hacked: - The multisig smart contract is owned - The computer you're signing on is owned - The hardware wallet (ledger, trezor) you're using is owned The multisig contract in question here (Gnosis Safe) has shown to be incredibly robust, and hardware wallets are very difficult to attack, so the current weak point is the computer. Cryptocurrency companies need to start…